“Prioritize patching CVE-2026-85880 and the SQL Server RCEs on all production systems before end of business today — don't wait for Tuesday testing cycles.”
Microsoft 365 Reportedly Down Again for Some Users — September 8, 2026
User reports of Microsoft 365 service disruption surged on DownDetector around 8:12 AM ET on September 8, just days after the resolution of the Sep 1–3 outage. The scope and cause have not yet been formally confirmed by Microsoft. MSPs should monitor the M365 Status Twitter account (@MSFT365Status) and the Service Health Dashboard in the Admin Center for real-time updates.
Read more →M365 Search Broken in SharePoint Online, OneDrive, Outlook Web & Desktop — Ongoing Reports
Users in multiple regions continue to report an inability to search for content across SharePoint Online, OneDrive, Outlook on the web, and Outlook desktop. Additionally, users in Japan have reported access issues affecting Teams and M365 broadly. Check Microsoft's Service Health Dashboard under your Admin Center for your tenant's specific incident ID.
Read more →CVE-2026-85880: Windows ALPC Zero-Day EoP — Actively Exploited, Patch Now
CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component, allowing a low-privilege AppContainer attacker to escape the sandbox and gain SYSTEM privileges with no user interaction required. Microsoft confirmed active exploitation in the wild prior to the patch being issued. Apply the September 2026 Patch Tuesday update immediately; no workaround is available — patching is the only remediation.
Read more →September Patch Tuesday Includes Four Critical SQL Server RCEs — Database Servers at Risk
Four critical remote code execution vulnerabilities affect Microsoft SQL Server in the September 2026 update, with databases often carrying sensitive business data and having privileged access to adjacent systems. September's release also patched 9 CVEs in Exchange Server and 16 in SharePoint Server. Apply the SQL Server cumulative update before end of week for any externally or internally accessible SQL instances.
Read more →Windows Kerberos RCE (CVE-2026-69676, CVSS 8.8) — Capture-Replay Attack, 'Exploitation More Likely'
CVE-2026-69676 is a critical RCE vulnerability in Windows Kerberos (CVSS 8.8) that allows a low-privilege attacker to exploit an authentication bypass via capture-replay techniques to execute arbitrary code. Microsoft rates this as 'Exploitation More Likely,' making it a priority patch for any environment with domain controllers or Kerberos-dependent services. Also patch Windows RRAS (CVE-2026-69590, CVE-2026-72950, CVE-2026-72959, CVE-2026-69852) on internet-facing or VPN-adjacent systems.
Read more →ConnectWise Sidekick Expanding AI-Assisted Ticket Triage and Documentation in 2026
ConnectWise Sidekick, embedded in the ConnectWise ecosystem, is gaining adoption for AI-driven ticket summarisation, response drafting, and documentation reduction — targeting the documented reality that labour represents 50–60% of MSP costs. Early data from MSPBots, a competing platform, shows up to 80% less dispatcher time and 23% faster SLA resolution through AI-driven workflow optimisation. MSPs evaluating AI service-desk tooling should pilot one platform against a defined ticket category before broad rollout.
Read more →ASIC Regulatory Strategy Update — September 2026 Parliamentary Testimony Has Compliance Implications for Fintech and MSP Clients
ASIC Chair Sarah Court's September 4 statement to the Parliamentary Joint Committee flagged a new Statement of Expectations requiring ASIC to weigh regulatory impact on small business and new entrants, alongside five updated priorities from the Corporate Plan 2026–27. MSPs serving financial services clients should review the updated ASIC Corporate Plan to identify any new cybersecurity, data handling, or reporting obligations affecting those clients. The full hearing transcript is available via the Parliamentary committee website.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.